{"id":"GHSA-mm57-9j6q-rxm2","summary":"Akka Java Serialization vulnerability","details":"Akka versions \u003c=2.4.16 and 2.5-M1 are vulnerable to a java deserialization attack in its Remoting component resulting in remote code execution in the context of the ActorSystem.","aliases":["CVE-2017-1000034"],"modified":"2023-11-08T03:58:41.898178Z","published":"2018-10-22T20:52:38Z","database_specific":{"github_reviewed_at":"2020-06-16T21:46:32Z","nvd_published_at":null,"cwe_ids":["CWE-502"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000034"},{"type":"WEB","url":"https://github.com/akka/akka/issues/22283"},{"type":"WEB","url":"https://github.com/akka/akka/commit/cc6561b47e5958923df520b8a9514010d3e11d49"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mm57-9j6q-rxm2"},{"type":"WEB","url":"http://doc.akka.io/docs/akka/2.4/security/2017-02-10-java-serialization.html"}],"affected":[{"package":{"name":"com.typesafe.akka:akka-actor","ecosystem":"Maven","purl":"pkg:maven/com.typesafe.akka/akka-actor"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.17"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-mm57-9j6q-rxm2/GHSA-mm57-9j6q-rxm2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}